Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

PENDING Check Online for Updates Missing in Win11 patched by SCCM

  • Thread starter Thread starter micahsd
  • Start date Start date
  • Replies Replies 2
  • Views Views 11K

micahsd

New Member
Messages
2
Reaction score
0
Points
1
My company uses SCCM for patching, however a handful of users like to manually use the "Check Online for Updates" link that would appear below the traditional "Check for Updates" option when running Windows Update manually on a system that is being patched by SCCM. That option is useful to get the latest drivers which Microsoft publishes or to download/install the MS updates prior to SCCM grabbing and updating the 'update' packages on the DP's. Below is a screen shot of the link that I'm referring to.
1634065329829.png

I noticed in Windows 11 that option does not appear on my system, although I can override it by changing the following registry key to override the WSUS Update Server which SCCM sets in the registry, then I'm able to use the Microsoft hosted Windows Update provider.
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU, then chnage the "UseWUServer" option to 0

Has anyone else noticed this? Or did Microsoft change where that "Check Online for Updates" option is located in Win11?

I know that by hitting the "Check for Updates" button in Win11 with SCCM/WSUS configured, it will return no results this afternoon after MS released their October updates. Once I changed that registry value and did another update check, it found the October updates and started downloading them from the internet.

Thanks.
 
Did some more research on Windows Update and I'm thinking maybe this option might be a better workaround. This appears to be a fairly new GPO option.

Located under the "Computer Configuration\Administrative Templates\Windows Components\Windows Update\Manage updates offered from Windows Server Update Service", the option to change is "Specify source service for specific classes of Windows Updates", enable it and set the options to look at "Windows Update" instead of WSUS.
1634067143091.png

I should've tried this before running Windows Update using that registry change to see if it would really download the latest updates from Windows Update.

Maybe someone else on here can confirm that or know of some other trick...I'll of course know next month.
 
When you are patching computers using ConfigMgr, why do you want users to manually check for updates ?. Isn't that dangerous because any user could download the updates in advance.
 

Forum statistics

Threads
7,133
Messages
27,856
Members
18,151
Latest member
TonyGTR
Back
Top